Endpoint Protection

 View Only
  • 1.  Vundu.gen

    Posted Apr 17, 2009 07:25 AM
    Hello Everyone and thanks for your help in advance.  I have an infected Windwos XP Pro workstation running Endpoint Security.  When running a full scan, Endpoint quarrantined Trojan:FakeAVAlert.  However, when running Microsoft Malicious Software Removal tool, several versions of the Vundu.gen virus appear, however, the tool does not seem to be able to remove it.  The workstation coontinues to suffer from numerous pop-ups and slow performance.  I am not sure where to go from here.  Any help would be greatly appreciated.


  • 2.  RE: Vundu.gen

    Posted Apr 17, 2009 08:12 AM
    Needless to say, If Symantec isnt able to completely remove it, You might have to use the third party tools
    MBAM (http://www.malwarebytes.org/) can save you lot of time if it succeeds.


  • 3.  RE: Vundu.gen

    Posted Apr 17, 2009 08:14 AM
     You might also want to submit samples so that Symantec builds ind etetction capabilities for this 


  • 4.  RE: Vundu.gen

    Posted Apr 17, 2009 08:46 AM

    You need to follow the standard procedure for removing malicious software.

    1. Disable system restore
    2. Reboot in and start in Safe Mode
    3. Use 3rd party or Symantec removal tool
    4. Boot in to windows again and do a full system scan (to make sure you really got rid of it)
    5. Patch XP with latest microsoft security patches.